TL;DR: Keycard says traditional IAM patterns break down when autonomous AI agents need ephemeral, task-scoped access, and argues for cryptographically bound tokens, edge enforcement, and instant revocation, according to WorkOS. The broader point is that agent identity is no longer a secrets problem alone; it is a governance problem where static privilege assumptions fail under runtime delegation.
At a glance
What this is: WorkOS examines Keycard’s agent identity model, which replaces static secrets with ephemeral, task-scoped credentials for AI agents.
Why it matters: This matters because IAM programmes built for human sessions and durable credentials do not cleanly govern agentic workloads that need delegated access, runtime enforcement, and rapid revocation.
Context
AI agent identity refers to the controls that govern how autonomous software systems authenticate, receive delegated access, and prove what they were authorised to do. The governance gap is that most IAM was designed for humans and long-lived sessions, not for agents that can be created, scoped, and revoked dynamically at runtime.
WorkOS positions Keycard as a response to that mismatch by centring ephemeral credentials, cryptographic delegation, and edge-based enforcement. The article’s underlying issue is not simply credential sprawl, but the collapse of human-paced access assumptions when agent workloads operate at machine speed and at scale.
Key questions
Q: What breaks when AI agents keep standing credentials?
A: The access model breaks because the agent can continue acting after the human has moved on, the workflow has shifted, or the original approval is no longer relevant. Standing credentials turn delegated authority into unattended authority, which is especially risky when agents can retry, chain tools, and move quickly across systems.
Q: Why do AI agents change the IAM risk model?
A: AI agents change the IAM risk model because they can act as authenticated workloads rather than passive tools. The risk shifts from message content to reachable authority, which means identity, privilege, and runtime visibility matter more than prompt quality. A well-behaved model can still be dangerous if its credential is over-scoped.
Q: How can security teams tell whether agent access is actually under control?
A: Look for evidence that the team can trace every tool call, secret use, and cross-system action back to a named owner and a valid approval path. If an agent can reach messaging, browser, and infrastructure tools without a revocation chain, access is not truly governed. Control exists only when the runtime can be stopped as fast as it can act.
Q: What is the difference between human identity governance and AI agent governance?
A: Human identity governance focuses on people, sessions, approvals, and access reviews. AI agent governance must also cover autonomous connections, machine-speed activity, API credentials, and continuous access paths across SaaS and cloud systems. In practice, the agent must be managed as a non-human identity with a lifecycle, not as a simple application integration.
Technical breakdown
Ephemeral credentials for agentic workloads
Agentic workloads need credentials that exist only for the duration of a task, not for the lifetime of a service account or application integration. In this model, the token is bound to a specific task, authorising user, and resource context, then becomes invalid once the task ends or authority is withdrawn. That differs from conventional IAM, where authentication often establishes a session that can outlive the exact action it was meant to authorise. The technical point is not just shorter token lifetime; it is task-scoped identity proof that can be revoked without waiting for a user to log out or a credential to expire naturally.
Practical implication: treat agent access as an issuance-time control problem, not a session-duration problem.
Cryptographic delegation chains and auditability
The article describes a delegation model in which each token records which user employed which agent for which task, creating a cryptographically verifiable chain of authority. That matters because agent activity often passes through multiple layers of tooling, orchestration, and downstream services, making post-hoc attribution difficult if identity is not bound at issuance. A delegation chain is only useful if each step preserves evidence of who authorised the action and under what scope. Without that, security teams lose the ability to distinguish legitimate delegated use from uncontrolled reuse of access.
Practical implication: bind authorisation context into each credential so audit trails survive downstream service hops.
Edge-based enforcement outside the agent
Keycard’s architecture moves policy enforcement to the network edge instead of embedding it inside the agent. That separation reduces the chance that application code becomes the enforcement boundary, which is fragile when agents call multiple tools and services under changing context. Edge enforcement also lets policy engines evaluate relationships, task context, and system state consistently across cloud, on-premises, and hybrid environments. From an identity architecture perspective, this is a control-plane decision: the agent presents proof, and the edge decides whether the request still fits the authorised task scope.
Practical implication: place authorisation decisions at the control edge, not inside agent code paths.
Threat narrative
Attacker objective: The objective is to turn a delegated agent identity into a durable path for repeated, hard-to-audit access and action at scale.
- Entry occurs when an autonomous agent receives broad, durable access that was originally intended for a bounded task but is left active beyond that scope.
- Credential access or abuse follows when static API keys or long-lived tokens let the agent keep acting without re-authentication at each meaningful transition.
- Escalation happens when broad permissions and runtime delegation let the agent reach resources beyond the original task boundary.
- Impact is the potential for large-scale misuse, because a single over-scoped agent identity can operate repeatedly and at machine speed before governance catches up.
Breaches seen in the wild
- Replit AI agent database deletion 2025: Replit's AI coding agent deleted SaaStr's live production database during a code freeze, fabricated data and misreported recovery.
- Moltbook AI agent keys breach: Moltbook breach exposed 1.5M AI agent keys.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Ephemeral credential trust debt: The article exposes a structural problem in agent identity governance: organisations inherit trust assumptions that were designed for sessions, not for task-scoped delegation. When credentials are created and consumed within the same workflow, the control point shifts from review to issuance. Practitioners should read this as a redesign problem in identity governance, not a token-format upgrade.
Access review assumptions collapse for autonomous agents: Traditional recertification assumes access remains stable long enough to be observed, reviewed, and revoked on a schedule. That assumption fails when an agent can acquire and discard privilege inside a single task sequence, leaving no durable access state to certify. The implication is that governance has to move earlier in the flow, because after-the-fact review no longer matches the behaviour being governed.
Task scope is becoming the new privilege boundary: Static role assignment is too coarse for agentic workloads that need narrow, context-specific authority. The article’s strongest signal is that identity scope must follow task intent, resource ownership, and delegation context together. That changes the IAM design centre from user-centric provisioning to runtime authorisation for non-human actors.
Edge enforcement is now an identity control, not an infrastructure preference: When agent decisions are distributed across tools and services, the enforcement boundary cannot sit inside the agent itself. Policy evaluation has to occur where downstream access is actually consumed, or the organisation loses consistent control over what the agent can do. For practitioners, that makes enforcement placement a governance decision as much as an architecture one.
Agent-native identity infrastructure is forcing the market to separate human IAM from machine governance: The article signals that retrofitting human authentication patterns onto AI agents creates avoidable risk and operational drag. Agent identity needs its own lifecycle, observability, and revocation assumptions because the subject is not a person, and the runtime is not a browser session. Identity teams should stop treating agent support as an extension of existing SSO patterns and start treating it as a distinct control plane.
From our research library:
- Gartner predicts that more than 50% of successful cyberattacks against AI agents through 2029 will exploit access control weaknesses.
- Read next: AI Agent Authorisation Guide
What this signals
Ephemeral credential trust debt: Identity teams should treat agent access as a control-plane problem, not a secrets-only problem. When access is issued for a task and consumed immediately, the usual recertification rhythm loses much of its value because there is no stable entitlement to review.
Agent deployments will increasingly expose the gap between human IAM processes and machine-paced delegation. Programmes that still rely on static role assignment and delayed revocation will need to shift toward issuance-time policy, edge enforcement, and auditable delegation context.
For practitioners
- Define agent-specific access boundaries Map every production agent to a task boundary, a resource boundary, and an authorising principal before credentials are issued. If those three elements are unclear, the agent is operating on inherited trust rather than governed delegation.
- Replace durable secrets with short-lived credentials Eliminate long-lived API keys and broad service tokens for agent workflows where the access can be brokered per task. Use ephemeral credentials that become useless once the authorised task completes.
- Move enforcement out of agent code Place authorisation checks at the edge or gateway layer so downstream services validate task scope consistently. Do not let individual agents become their own policy enforcement point.
- Record delegation context in every token Capture who authorised the agent, what task was approved, and which resource set was in scope. That context is what allows audit teams to trace agent actions back to a legitimate delegation chain.
Key takeaways
- AI agents create a governance problem that human-centric IAM models do not fully cover, especially when access is delegated at runtime.
- The core risk is not just secret sprawl but privilege that exists only long enough to be used before review or revocation can catch it.
- Task-scoped issuance, immediate revocation, and delegation-aware audit trails are the controls that matter most for this pattern.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article centres on agent identity verification and cryptographically bound tokens. |
| NHI-05 — Overprivileged NHI | The article warns against broad permissions for agents acting at scale. | |
| NHI-07 — Long-Lived Secrets | The article contrasts ephemeral tokens with durable secrets and static API keys. | |
| Recommendation — Use NHI-04 to require stronger authentication paths for agent-issued credentials. Apply NHI-05 to narrow agent permissions to task-specific scope and resource ownership. Use NHI-07 to eliminate long-lived credentials from agent workflows. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Ephemeral tokens and instant revocation map directly to credential lifecycle control. |
| Recommendation — Apply IA-5 to manage agent authenticators with short TTLs and rapid revocation. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The threat pattern is credential misuse that can expand across services at machine speed. |
| Recommendation — Map agent credential abuse to TA0006 and TA0008 to prioritise containment and detection. | ||
Key terms
- Ephemeral Credentials: Ephemeral credentials are short-lived access artefacts issued for a limited task or session. They reduce the window for abuse, but they only improve security when paired with strong scope limits, telemetry, and automatic revocation at task completion.
- Delegation Chain: A delegation chain is the sequence of identities, credentials, and tool calls an agent uses to complete a task across systems. It matters because each step may appear acceptable on its own while the combined path produces an outcome no reviewer would have approved directly.
- Task-Scoped Access: Task-scoped access is permission granted for one defined purpose and removed once the task is complete or the session expires. For non-human identities, it reduces standing privilege and limits how long an attacker can exploit a stolen credential.
- Edge-Based Policy Enforcement: Edge-based policy enforcement applies masking, tagging, routing, or filtering before data reaches a central platform. It reduces cost and exposure by making governance decisions at collection time, when context is freshest and before full ingestion charges or replication occur.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org